Supabase PGRST301 JWT invalid: the anon key and service role key are not interchangeable
Fix for Supabase PGRST301 JWT invalid: the anon key and service role key are not interchangeable: After any key rotation in the dashboard, update every consumer: frontend env, Edge Function secrets, server env, CI. Use this when you hit exactly this in Supabase PGRST301 JWT invalid. Not for different errors or different tools.
TL;DR: After any key rotation in the dashboard, update every consumer: frontend env, Edge Function secrets, server env, CI. # PGRST JWT errors: which key, which project, which purpose PostgREST validates the JWT on every request. When it fails, agents cycle through random fixes.
Supabase PGRST301 JWT invalid: the anon key and service role key are not interchangeablePGRST JWT errors: which key, which project, which purpose
PostgREST validates the JWT on every request. When it fails, agents cycle through random fixes. The failure modes are a short list, and each has a distinct signature.
Symptom to cause to confirmation to fix
- Confirm the key belongs to this project. Keys are per project; a key from project A against project B's URL fails validation. This happens when env files are copied between projects.
- Confirm you are not sending the service role key as the Authorization bearer for user-scoped requests and then wondering why RLS does not apply. The service role key is not a JWT for a user; it bypasses RLS. User requests need the anon/publishable key plus the user's JWT.
- After any key rotation in the dashboard, update every consumer: frontend env, Edge Function secrets, server env, CI. A stale key fails validation immediately and everywhere at once, which is the signature of a missed consumer, not a platform outage.
- Check the clock. "JWT issued in the future" variants come from clock skew between the issuer and the validator. (A related skill covers the PGRST303 future-issued case with the new secret keys.)
- Decode the JWT payload (without verifying) and check the
roleclaim and expiry.role: service_roleon a user request or anexpin the past tells you exactly which mistake was made.
Verification
Make the same request with a freshly copied anon key and a fresh user JWT from the dashboard. If it works, the old key material was the problem; find every place it was cached.
When to use
You hit exactly this: Supabase PGRST301 JWT invalid: the anon key and service role key are not interchangeable in Supabase PGRST301 JWT invalid.
When not to use
A different error, or the same symptom in a different tool. This page only covers the failure above.
Compatibility
Supabase PGRST301 JWT invalid.
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.